Adware, malware, spyware, hijacker discussion and information

[Gain Knowledge]  [Install Prevention]  [Maintain Security]  [Spyware Removal Help]


It is currently Sat Jul 31, 2010 2:20 pm

All times are UTC - 7 hours




Post new topic Reply to topic  [ 3 posts ] 
Author Message
 Post subject: New Attacks Against Internet Explorer
PostPosted: Mon Jul 06, 2009 9:05 am 
Offline
Site Admin
Site Admin
User avatar

Joined: Fri Jan 28, 2005 5:16 pm
Posts: 15493
Location: PHX, AZ
Monday July 6, 2009 at 2:39 am CST
Posted by Haowei Ren, Geok Meng Ong

If you have read Geok Meng and Xiaobo’s blog published in December last year, this would almost seem like a movie sequel. Over the July 4th weekend, an exploit targeting a 0-day vulnerability in the Microsoft Microsoft DirectShow ActiveX object was widely discovered on many Chinese websites.

At the time of research, over a hundred hijacked sites were found to be injected with malicious links that are still actively hosting this trojan. Many of these sites are what you and I would not consider to be “malicious” or “dodgy”. For example, some of them are school websites or the local community club’s website that had been hijacked or infected.

During research, one of the things we found interesting was the web exploit toolkit explicitly checks that the origin of the hyperlinked references do not come from the “.gov.cn” and “.edu.cn” domains, which are used by Chinese government and education sites. If the references are not coming from any of these domains, it starts sending a cocktail of exploits:
    Exploit-MSDirectShow.b (0-day)
    Exploit-XMLhttp.d
    Exploit-RealPlay.a
    JS/Exploit-BBar
    Exploit-MS06-014

0-= Continued @ McAfee Avert Labs Blog

_________________
Image


Top
 Profile Send private message  
 
 Post subject: Re: New Attacks Against Internet Explorer
PostPosted: Tue Jul 07, 2009 4:04 pm 
Offline
Security Researcher
Security Researcher

Joined: Mon Dec 29, 2008 9:45 am
Posts: 6
SANS has a page tracking all the sites that are exploiting this vulnerability. Check it out here:
http://isc.sans.org/diary.html?storyid=6739

--mwdisector


Top
 Profile Send private message E-mail  
 
 Post subject: Re: New Attacks Against Internet Explorer
PostPosted: Tue Jul 07, 2009 4:13 pm 
Offline
Site Admin
Site Admin
User avatar

Joined: Fri Jan 28, 2005 5:16 pm
Posts: 15493
Location: PHX, AZ
mwdisector wrote:
SANS has a page tracking all the sites that are exploiting this vulnerability. Check it out here:
http://isc.sans.org/diary.html?storyid=6739

--mwdisector
Thanks!

_________________
Image


Top
 Profile Send private message  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC - 7 hours


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  

Who is online

Who is online In total there is 1 user online :: 0 registered, 0 hidden and 1 guest (based on users active over the past 5 minutes)
Most users ever online was 115 on Tue Jul 13, 2010 5:32 pm

Users browsing this forum: No registered users and 1 guest

New posts    No new posts    Forum locked
cron
Powered by phpBB